Skip to main content
gateway_attestation is evidence for the NEAR AI Cloud gateway. It is not evidence for a model environment. Use model attestations when your policy also requires model evidence.

Request gateway evidence

Generate the nonce in your client. It must be 32 random bytes encoded as 64 hexadecimal characters.
The response contains the gateway report at gateway_attestation. For a deployment-first completion, verify and retain it before sending the completion. Add model=<MODEL_ID>, provider=near, and the x-no-aliasing: true header when you also need NEAR model evidence. That request returns NEAR model reports in model_attestations[]; verify every entry before sending the completion. Add include_tls_fingerprint=true only when you are following the NEAR AI Cloud gateway TLS flow.

Verify the gateway report

For gateway_attestation:
  1. Verify intel_quote with an Intel DCAP quote verifier, such as dcap-qvl, and apply your TCB and advisory policy.
  2. Read report_data and measurements from the verified quote, not only from fields echoed in the HTTP response. Reject the report if its echoed request_nonce or report_data is missing or differs from the nonce and report data you verified.
  3. Check that the verified quote binds the nonce generated by your client and the reported signing_address. Use signing_algo to interpret that identity and verify response signatures.
  4. Replay event_log as described in Replay the RTMR3 event log and require the result to equal the RTMR3 in the verified quote.
  5. Obtain the raw info.tcb_info.app_compose string. If tcb_info is JSON text, decode it first. Hash app_compose without parsing or reserializing it, and require the quote’s 48-byte MRCONFIGID to equal 01, then that SHA-256 hash, then 15 zero bytes. See Check the configuration measurement.
  6. When a TLS fingerprint was requested, verify its binding as part of the NEAR AI Cloud gateway TLS flow.
  7. Apply your accepted measurement and image-provenance policy.
The verified quote is the cryptographic source of truth. The HTTP fields are consistency checks, not a substitute for quote verification.

Field scope

Freshness and failure handling

The nonce establishes freshness only when the client generated and retained it, and the verified quote contains that nonce. If the report is unavailable, the quote fails, the nonce does not match, or the identity does not match, treat the gateway property as unverified. For a deployment-first response-signature flow, retain this verified report and require a later gateway signature to match its signer and algorithm. A report fetched after the completion cannot replace that preflight evidence, and a report from another signer is not a substitute.